I'm Paul Gibson. I write the plain-English version of identity & access governance — the unglamorous corner of security where most breaches quietly begin. Identity, in simple terms.
Identity governance decides who can open which door — and, more importantly, who still can when they shouldn't. It's where budgets, audits and breaches all quietly collide. I explain it in plain English: the boring things that cost real money, told with the occasional straight face.
Short, plain-English pieces on the parts of identity everyone pretends are fine. New writing lands on LinkedIn a few times a week.
The employee who resigned years ago, whose access politely stayed behind.
More access than you, a password from 2021, and everyone too scared to switch it off.
What "yes, approved" actually means when 400 lines need rubber-stamping by Friday.
We check the humans at the door while the service accounts climb in the window.
How to justify identity in money and risk, not features and acronyms.
Why the person who bakes the cake shouldn't also count the till.
I've spent about thirty years in cyber and identity — the last five running identity governance inside large financial-services organisations. Long enough to watch the same expensive mistakes repeat in slightly different fonts.
I started writing because the good explanations were all either sales pitches or 400-page standards, with nothing in between for the humans who actually have to run this stuff. So that's what I do here: the practitioner's plain-English take.
I'm also training as a speaker over the next year — so expect more of this out loud, on stages and podcasts, soon.
The writing lives on LinkedIn for now. Connect there for the plain-English identity pieces — or just to tell me which of the above you've lived through.